Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 10 discussion

Actual exam question from Isaca's CISM
Question #: 10
Topic #: 1
[All CISM Questions]

Which of the following is the MOST effective way to address an organization's security concerns during contract negotiations with a third party?

  • A. Review the third-party contract with the organization's legal department.
  • B. Communicate security policy with the third-party vendor.
  • C. Ensure security is involved in the procurement process.
  • D. Conduct an information security audit on the third-party vendor.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
ccKane
Highly Voted 1 year, 9 months ago
Selected Answer: C
Ensuring security is involved in the procurement process is the most effective way to address an organization's security concerns during contract negotiations with a third party. Involving security personnel in the procurement process allows the organization to identify and address potential security risks early on, before a contract is signed. This helps ensure that security requirements are included in the contract and that the third-party vendor is aware of and committed to meeting the organization's security standards. By having security involved in the procurement process, the organization can also ensure that the third-party vendor has adequate security controls in place to protect sensitive information and critical assets. This can include reviewing the vendor's security policies, conducting security assessments, and verifying that the vendor is in compliance with relevant laws and regulations.
upvoted 8 times
...
mfourati
Highly Voted 1 year, 11 months ago
Answer B is completely wrong, communicating the policy to the third party does not grantee the third party will enforce the proper measures
upvoted 5 times
...
Prospect57
Most Recent 1 month, 3 weeks ago
Selected Answer: C
Answer: C. Due diligence activities are: Requirements, Questionnaire, Supplier Interviews, Risk Analysis, & Contract. Security should be included as soon as possible to define Requirements.
upvoted 1 times
...
Viperhunter
1 month, 3 weeks ago
Selected Answer: C
By involving the security team in the procurement process, you can proactively address security concerns from the outset. This allows security professionals to assess the third party's security posture, ensure that security requirements are adequately addressed in the contract, and provide valuable input to the negotiation process. It helps in aligning the security needs of the organization with the contractual agreements, leading to a more secure and compliant relationship with the third party. While other options, such as reviewing the contract with the legal department (option A), communicating security policies with the third-party vendor (option B), and conducting an information security audit (option D) are important steps, involving security in the procurement process is the proactive approach that can prevent security issues before they arise.
upvoted 1 times
...
CISSPST
1 month, 3 weeks ago
Selected Answer: C
The most effective way to address an organization's security concerns during CONTRACT NEGOTIATIONS with 3rd party is C. It will be impossible for security to do either A, B or D without first being involved in the procurement process. Agreed that they may be involved if and when required, but that wouldn't be the most effective way. A. Security and legal along with other stakeholders will review the contract, provided security is involved in the procurement process. B. Security policy can be communicated to the 3rd party only if security is involved in the procurement process. D. If warranted, security audit can be performed on 3rd party, but this isn't possible unless security is involved in the procurement process.
upvoted 1 times
...
oluchecpoint
1 month, 3 weeks ago
Selected Answer: C
By ensuring security is involved in the procurement process (Option C), you proactively consider security requirements and risks from the beginning, which can help in selecting vendors that align with your security needs and potentially avoiding security issues down the road. This approach is proactive and holistic in addressing security concerns during contract negotiations.
upvoted 1 times
...
greeklover84
2 months ago
Selected Answer: C
I agree C seems to be correct.
upvoted 1 times
...
Cyberbug2021
12 months ago
Selected Answer: C
Question is about on going negotiations - security should be involved to address the security concerns - Legal cannot do that. And just communicating those concerns to the vendor also does not address them.
upvoted 1 times
...
Manix
1 year ago
Selected Answer: B
Contract negotiations are ongoing, security is involved. Then it's B
upvoted 1 times
Cyberbug2021
12 months ago
How do you know security is involved? its one of the options in the answer so it comes first - before B
upvoted 1 times
...
...
oluchecpoint
1 year, 2 months ago
By ensuring security is involved in the procurement process (Option C), you proactively consider security requirements and risks from the beginning, which can help in selecting vendors that align with your security needs and potentially avoiding security issues down the road. This approach is proactive and holistic in addressing security concerns during contract negotiations.
upvoted 1 times
...
sbbrn
1 year, 2 months ago
Selected Answer: C
I choose "C" as communicating security policy does not necessarily "ensure" that the contract will address the security requirements. Option "B" says "ensure" meaning a definitive and effective outcome
upvoted 1 times
...
pc2502
1 year, 3 months ago
I had confusion between B and D but looks less feasible we the org have that power to go for audit by so B looks more relevant
upvoted 2 times
...
Dopy
1 year, 4 months ago
Selected Answer: B
it states during contract negotiations
upvoted 2 times
...
Dopy
1 year, 4 months ago
Selected Answer: B
it has gone past the procurement process and is in contract negotions, so answer is B
upvoted 1 times
...
peelu
1 year, 5 months ago
Selected Answer: C
Ensuring security is involved in the procurement process
upvoted 1 times
...
richck102
1 year, 6 months ago
C. Ensure security is involved in the procurement process.
upvoted 1 times
...
Tony202200
1 year, 6 months ago
I think D is incorrect since the contract has not been signed. The 2 sides are still negotiating and auditing efforts will be futile if the contract is not signed. Option C is also incorrect since procurement happens after contract sign off. The procurement team can sit at the negotiation table but the process of procuring materials is yet to start since there is no sign off. Option B looks appealing where the policy is shared with the vendor which is a top level administrative control. Contract negotiations more than likely happen at the exec level where it is all about policies. I vote C
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...